Analysis of DragonForce Windows Ransomware Locker
Score: 9/10

Analysis of DragonForce Windows Ransomware Locker

DragonForce is a ransomware service ecosystem deploying Windows lockers that use ChaCha8 encryption and target SMB shares to maximize network impact.

Executive Summary

DragonForce is a Ransomware-as-a-Service (RaaS) ecosystem that emerged in late 2023, gaining significant traction in 2025 and 2026. The group has been linked to disruptive attacks against UK retail sectors and is frequently deployed by affiliates such as Octo Tempest. While the ecosystem supports a wide range of intrusion activities, the core Windows locker is a specialized impact tool designed for high-speed encryption of local and network-accessible data.

The technical analysis reveals a network-aware but non-wormable locker. It utilizes ChaCha8 for file encryption and RSA-4096 for recovery material protection, featuring specialized modes for handling large database and virtual machine files. The locker is capable of terminating 38 specific processes and inhibiting recovery by deleting shadow copies via WMI/WMIC.

DragonForce represents a significant threat to manufacturing, professional services, and technology sectors due to its ability to damage large-scale assets quickly. Although it lacks autonomous propagation and exfiltration code, its ability to enumerate and encrypt all writable SMB shares under a compromised security token allows a single infected host to cause widespread operational downtime.

Key Details

Threat Name

DragonForce Ransomware

Affects

—

Adversary

DragonForce Other Adversaries and Aliases: Octo Tempest; LockBit; Qilin

Malware/Tools

DragonForce, LockBit, Qilin

Report Score

9out of 10
Quality Score
Excellent
IOC Quality9
TTP Details9
Detection Guidance8
Enterprise Relevance9
Clarity & Structure9
Technical Depth9

Sources